Spring XML配置:如何将静态final RequestMatcher作为Bean构造器参数?
Spring Security 5.2.15 配置CSRF并注入DEFAULT_CSRF_MATCHER的正确方式
问题原因分析
你遇到的两个错误本质是配置语法不符合Spring XML Schema规范和AndRequestMatcher的构造方法要求:
- 找不到AndRequestMatcher构造方法:AndRequestMatcher在5.2.x版本中核心构造方法接收
List<RequestMatcher>类型参数,直接传递单个/多个独立的RequestMatcher实例会匹配不到对应构造方法。 - b:value属性错误:XML中
<value>标签本身不需要额外的value属性,错误写法(如<b:value value="xxx"/>)违反了Schema约束。
解决方案
根据你的需求(给特定URL禁用CSRF,同时注入CsrfFilter.DEFAULT_CSRF_MATCHER),以下是两种可行的配置方式:
1. XML配置方式
需引入util命名空间来引用静态常量,同时正确构造AndRequestMatcher的参数列表:
<beans xmlns="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:sec="http://www.springframework.org/schema/security" xmlns:util="http://www.springframework.org/schema/util" xsi:schemaLocation=" http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security.xsd http://www.springframework.org/schema/util http://www.springframework.org/schema/util/spring-util.xsd"> <!-- 定义需要排除CSRF校验的URL匹配器 --> <bean id="excludedCsrfUrls" class="org.springframework.security.web.util.matcher.AntPathRequestMatcher"> <constructor-arg value="/api/**"/> <!-- 替换为你的目标URL --> </bean> <!-- 构造自定义CSRF匹配器:默认规则 + 排除指定URL --> <bean id="csrfMatcher" class="org.springframework.security.web.util.matcher.AndRequestMatcher"> <constructor-arg> <list> <!-- 注入静态常量DEFAULT_CSRF_MATCHER --> <util:constant static-field="org.springframework.security.web.csrf.CsrfFilter.DEFAULT_CSRF_MATCHER"/> <!-- 通过NegatedRequestMatcher排除指定URL --> <bean class="org.springframework.security.web.util.matcher.NegatedRequestMatcher"> <constructor-arg ref="excludedCsrfUrls"/> </bean> </list> </constructor-arg> </bean> <!-- 在Spring Security核心配置中使用自定义匹配器 --> <sec:http> <!-- 其他安全配置(如授权、登录等) --> <sec:csrf matcher-ref="csrfMatcher"/> </sec:http> </beans>
2. Java配置方式(推荐)
如果项目支持JavaConfig,这种方式更简洁且不易出错:
import org.springframework.context.annotation.Bean; import org.springframework.context.annotation.Configuration; import org.springframework.security.config.annotation.web.builders.HttpSecurity; import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter; import org.springframework.security.web.csrf.CsrfFilter; import org.springframework.security.web.util.matcher.AndRequestMatcher; import org.springframework.security.web.util.matcher.AntPathRequestMatcher; import org.springframework.security.web.util.matcher.NegatedRequestMatcher; import org.springframework.security.web.util.matcher.RequestMatcher; @Configuration public class SecurityConfig extends WebSecurityConfigurerAdapter { // 构造自定义CSRF匹配器Bean @Bean public RequestMatcher csrfMatcher() { // 定义需要排除的URL规则 RequestMatcher excludedUrls = new AntPathRequestMatcher("/api/**"); // 组合默认CSRF匹配规则和排除逻辑 return new AndRequestMatcher( CsrfFilter.DEFAULT_CSRF_MATCHER, new NegatedRequestMatcher(excludedUrls) ); } @Override protected void configure(HttpSecurity http) throws Exception { http // 其他安全配置(如.authorizeRequests()等) .csrf(csrfConfig -> csrfConfig .requireCsrfProtectionMatcher(csrfMatcher()) ); } }
内容的提问来源于stack exchange,提问作者Myy
相关产品推荐
相关产品推荐

